First published: Fri Nov 01 2019(Updated: )
minidlna has SQL Injection that may allow retrieval of arbitrary files
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Readymedia Project Readymedia | <1.1.0 | |
debian/minidlna | 1.3.0+dfsg-2+deb11u2 1.3.0+dfsg-2.2+deb12u1 1.3.3+dfsg-1 1.3.3+dfsg-1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2738 is a vulnerability in minidlna that allows for SQL Injection, which can be exploited to retrieve arbitrary files.
The severity of CVE-2013-2738 is critical, with a severity value of 9.8.
minidlna versions 1.2.1+dfsg-2+deb10u3, 1.2.1+dfsg-2+deb10u4, 1.3.0+dfsg-2+deb11u2, 1.3.0+dfsg-2.2+deb12u1, and 1.3.3+dfsg-0.1 are affected.
To fix CVE-2013-2738, please update your minidlna software to a version that includes the necessary security patches.
You can find more information about CVE-2013-2738 at the following references: [Link 1](http://archives.neohapsis.com/archives/bugtraq/2013-07/0100.html), [Link 2](http://media.blackhat.com/bh-us-12/Briefings/Cutlip/BH_US_12_Cutlip_SQL_Exploitation_WP.pdf), [Link 3](https://security-tracker.debian.org/tracker/CVE-2013-2738).